GOVERNANCE & DATA PROTECTION

Responsible stewardship of information

At Sian Gissing Strategic Legal Consultancy, responsible information governance is fundamental to the way we operate.

Clients may entrust us with personal information, sensitive circumstances, identity documents, financial records, correspondence and commercially or legally significant material. We recognise that this information has both personal and economic value and must be handled with care, discretion and accountability.

Misused, inaccurately recorded or inadequately protected information can expose individuals and businesses to fraud, identity theft, financial loss, reputational harm, privacy infringements and avoidable mistakes.

Data protection is therefore not treated as an administrative formality. It forms an integral part of our ethical standards, professional judgment and commitment to responsible stewardship.

Data controller and ICO registration

Sian Gissing Global Holdings Ltd, trading as Sian Gissing Strategic Legal Consultancy, is registered with the Information Commissioner’s Office as a data controller.

ICO registration reference: ZC208021
Registration commenced: 27 July 2026
Current registration expiry: 26 July 2027
Person responsible for data protection: Ms Sian Gissing

Our registration can be verified through the ICO Register of Fee Payers.

Registration with the ICO demonstrates that the company is listed on the public register of data-protection fee payers and acknowledges its responsibilities when processing personal information. It does not constitute ICO approval, accreditation or endorsement of our consultancy services.

 

Our governance principles

Our approach to data governance is guided by the following principles:

Lawfulness, fairness and transparency

Personal information should be processed lawfully, fairly and transparently. Clients should understand why information is required, how it may be used and with whom it may need to be shared.

Consent is not the only lawful basis upon which personal information may be processed. Depending on the circumstances, processing may also be necessary to perform a contract, comply with a legal obligation, protect legitimate interests or establish, exercise or defend legal rights.

Where consent is the appropriate lawful basis, it should be informed, specific and capable of being withdrawn.

Purpose limitation

Information should be collected for a clear, legitimate and defined purpose. It should not be used incompatibly, excessively or opportunistically for unrelated purposes.

Data minimisation

We seek to collect and retain only the information reasonably necessary to assess an enquiry, deliver an agreed consultancy service, manage the professional relationship or satisfy an applicable legal or regulatory obligation.

Accuracy

Reasonable steps are taken to ensure that personal information is accurate and, where necessary, kept up to date. Clients are encouraged to notify us when their information changes or when they believe a record is inaccurate.

Proportionality

We understand the important distinction between the legitimate and proportionate use of information and its excessive, unauthorised or unlawful use.

Our decision-making considers whether the proposed use of information is necessary, relevant and proportionate to the purpose being pursued.

Retention and secure disposal

Personal information is not intended to be kept indefinitely. Retention periods are informed by the nature of the information, the purpose for which it was collected and any contractual, legal, regulatory, insurance or dispute-related requirements.

When information is no longer reasonably required, it will be securely deleted, destroyed or anonymised where appropriate.

Accountability

We take responsibility for the information entrusted to the consultancy. This includes maintaining appropriate policies, records, contractual safeguards and procedures designed to support lawful and responsible information handling.

Confidential client information

Confidentiality and discretion are central to our client relationships.

Access to client information is limited to those who reasonably require it for a legitimate business or professional purpose. Information will not be sold or knowingly disclosed for unrelated commercial use.

Client information may be shared where reasonably necessary:

  • to provide an agreed consultancy service;
  • with a service provider supporting the secure operation of the consultancy;
  • with a professional adviser or third party authorised by the client;
  • to comply with a lawful request, court order or legal obligation;
  • to prevent or investigate suspected fraud, misuse or security incidents; or
  • to establish, exercise or defend legal rights.

Where another professional must be instructed or confidential information must be disclosed outside the agreed scope, the client’s authority will ordinarily be obtained unless disclosure is otherwise required or permitted by law.

The confidentiality applying to consultancy communications should not automatically be interpreted as legal professional privilege. Whether privilege applies depends upon the circumstances and the legal status and role of the relevant adviser.

Information security

We apply appropriate technical and organisational measures proportionate to the nature and sensitivity of the information being processed.

These measures may include:

  • controlled access to client records;
  • password protection and multi-factor authentication;
  • secure client portals and encrypted document-transfer facilities;
  • electronic identity and signature systems;
  • secure storage and organised file-management procedures;
  • data minimisation and access limitation;
  • security reviews and software updates;
  • confidentiality controls for service providers; and
  • incident identification, assessment and response procedures.

Where appropriate, clients may be provided with access to a secure client portal for uploading documents and communicating with the consultancy.

No method of electronic transmission or storage can be guaranteed to be completely secure. Our responsibility is to assess relevant risks and maintain safeguards appropriate to the nature of the information and the services provided.

Third-party service providers

The consultancy uses carefully selected technology and professional service providers to support functions such as:

  • client relationship and matter management;
  • secure document collection and storage;
  • electronic signatures;
  • appointment booking and video conferencing;
  • website operation and hosting;
  • payment processing;
  • accounting and administration; and
  • professional communications.

These providers may process limited personal information on our behalf or act as independent data controllers for particular services. Appropriate contractual, confidentiality and data-protection considerations are applied according to the provider’s role.

Some providers may process or store information outside the United Kingdom or European Economic Area. Where applicable, appropriate safeguards will be considered for international transfers of personal information.

Further details about categories of recipients and international transfers are provided in our Privacy Policy or may be requested by contacting us.

Your data-protection rights

Subject to applicable law and any relevant exemptions, individuals may have the right to:

  • be informed about the processing of their personal information;
  • request access to their personal information;
  • request correction of inaccurate or incomplete information;
  • request erasure of information in certain circumstances;
  • request restriction of processing;
  • object to certain processing;
  • request data portability where applicable;
  • withdraw consent where processing relies upon consent; and
  • raise concerns about automated decision-making, where applicable.

These rights are not absolute and may be limited by legal, contractual, regulatory or evidential requirements.

We may need to verify a requester’s identity before disclosing or altering personal information. This protects individuals against unauthorised access, fraud and impersonation.

Data incidents and concerns

Any suspected loss, misuse, unauthorised disclosure or security compromise involving personal information is assessed promptly and proportionately.

Where legally required, an incident will be reported to the Information Commissioner’s Office or another relevant supervisory authority, and affected individuals will be informed where the applicable notification threshold is met.

Clients should notify us promptly if they believe information has been sent to the consultancy incorrectly, accessed without authority or otherwise compromised.

Enquiries, rights requests and complaints

Questions, rights requests or concerns about the use of personal information should initially be directed to:

Ms Sian Gissing
Person responsible for data protection
Sian Gissing Global Holdings Ltd
Trading as Sian Gissing Strategic Legal Consultancy
Email: legal@siangissing.com
Website: www.siangissing.com

We will seek to acknowledge and address data-protection concerns carefully, transparently and within the applicable legal timeframe.

Individuals also have the right to complain to the Information Commissioner’s Office:

www.ico.org.uk
Telephone: 0303 123 1113

If another data-protection supervisory authority has jurisdiction, individuals may also have the right to submit a complaint to that authority.

Our commitment

Trust is built through more than words. It requires sound judgment, secure systems, clear boundaries and accountability.

Our commitment is to treat personal and business information as an entrusted asset: using it only where there is a legitimate and proportionate reason, protecting it with appropriate safeguards and respecting the rights of the people to whom it relates.

This reflects the wider values of Sian Gissing Strategic Legal Consultancy:

Clarity over chaos. Discretion over exposure. Stewardship over misuse. Accountability in every decision.

 

Last updated: 4 August 2026